Cybersecurity incidents are correlated to identify patterns, trends, and other common features across multiple incidents
Correlation of incidents can be done through analysis, incident tracking tools, use of incident categories, and matching terms in logs. For example, system access logs can be checked for system authentication failures, and the IP addresses from those can be correlated with known malicious IP addresses gathered through intelligence sources.
Related Practices · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: RESPONSE-2b, RESPONSE-2d, RESPONSE-2f, RESPONSE-2i.